HIGH 7.5 GitHub
CVE-2026-19481
@fastify/busboy vulnerable to Denial of Service via prototype-named multipart part header
### Impact
Versions of `@fastify/busboy` from 1.0.0 and prior to 3.2.1 are vulnerable to a Denial of Service. The multipart header parser stores part-header names on a plain JavaScript object, so a part header named `__proto__` or `constructor` resolves to an inherited value that is not an array, and the parser throws `TypeError: this.header[h].push is not a function`. Through the documented `req.pipe(busboy)` integration this surfaces as an `error` event, while direct `write()`/`end()` usage t
Affected Products
- npm/@fastify/busboy >= 1.0.0, < 3.2.1
References
- https://github.com/advisories/GHSA-x8mw-p69m-v3mx
- https://github.com/fastify/busboy/security/advisories/GHSA-x8mw-p69m-v3mx
- https://nvd.nist.gov/vuln/detail/CVE-2026-19481
- https://github.com/fastify/busboy/commit/957a24b66d5915e6d0a6ac988c9dbcee86373e9b
This high severity vulnerability with a CVSS score of 7.5 was published on 2026-10-02 via GitHub. Affected: npm/@fastify/busboy >= 1.0.0, < 3.2.1.
vulnfeed aggregates 9972 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.